← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — India Country Annex

Effective date: 19 July 2026 Last updated: 19 July 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Indian resident covered by this Annex; the contact person discharging the Data Fiduciary contact-publication duty under the Digital Personal Data Protection Act, 2023 (the "DPDP Act") Section 5(1)(iii) read with the Digital Personal Data Protection Rules, 2025 (notified 14 November 2025, the "DPDP Rules 2025") — the business contact for the purposes of answering questions about the processing of personal data is ; the designated contact point for the Data Protection Board of India (the "Board"), the Ministry of Electronics and Information Technology ("MeitY"), the Indian Computer Emergency Response Team ("CERT-In"), the National Crime Records Bureau / National Cyber Crime Reporting Portal, and the Central Consumer Protection Authority ("CCPA"), under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023, assented 11 August 2023) or any change in the phased commencement of its provisions; (b) any amendment to the DPDP Rules 2025 (notified 14 November 2025 with phased commencement — verify the rules in force at each review) or any further rules, notifications, or standards issued under DPDP Act Section 40; (c) any notification by the Central Government under DPDP Act Section 16 restricting transfer of personal data to any country or territory outside India (none notified at the Effective date); (d) any exemption notification under DPDP Act Section 9(5) or any change to the Fourth Schedule of the DPDP Rules 2025 (Part B "safety of the child" purposes); (e) any designation of Balance as a Significant Data Fiduciary under DPDP Act Section 10 (not designated at the Effective date); (f) any amendment to the Information Technology Act, 2000 ("IT Act") — in particular Section 67B (child sexual abuse material) — or to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("IT Rules 2021"); (g) any amendment to the Protection of Children from Sexual Offences Act, 2012 ("POCSO") — in particular the Section 19 mandatory-reporting duty and Sections 13-15 (child pornography offences); (h) any amendment to the Consumer Protection Act, 2019 ("CPA 2019") or the Consumer Protection (E-Commerce) Rules, 2020; (i) any decision of the Supreme Court of India or a High Court bearing on the DPDP Act or on the constitutional right to privacy under Justice K.S. Puttaswamy (Retd.) v Union of India (2017) 10 SCC 1 (Article 21); (j) any amendment to the Bharatiya Nyaya Sanhita, 2023 insofar as it engages child-protection or obscenity offences; (k) any change to a sub-processor's India data-handling posture under our sub-processor register; (l) the bringing into force of any post-Effective-date Indian regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (m) any CERT-In direction (including the CERT-In Directions of 28 April 2022 on incident reporting) that materially alters the operational rules below. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Indian-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants an Indian resident a right that the global Policy does not, this Annex governs. Where the global Policy grants an Indian resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. English is one of the two official languages of the Union under the Constitution of India Article 343 read with the Official Languages Act, 1963, and is an accepted language for the DPDP Act Section 5 notice. DPDP Act Section 5(3) gives the Data Principal the option to access the notice in English or any of the twenty-two languages specified in the Eighth Schedule to the Constitution of India; Balance provides the notice in English and will provide an Eighth-Schedule-language rendering of the Section 5 notice on request at (per the locked product decision, the published documentation set for India is English-only at the Effective date).


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is India — the Union of India comprising 28 States and 8 Union Territories. The DPDP Act is a Union statute enacted under the Seventh Schedule; there is no State-level data-protection sub-layer that derogates from the DPDP Act in respect of Balance's processing.

We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region. Where any of the three signals identifies India, this Annex applies; the most-protective-for-the-data-subject reading controls per our internal compliance plan § 6.3.

The DPDP Act has explicit territorial reach defined at Section 3(b): the Act applies to processing of digital personal data outside the territory of India if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India. Balance offers its service to Indian residents through Google Play India and through publication of this Annex; the DPDP Act applies in respect of all personal data Balance processes in connection with Indian-resident users via the Section 3(b) offer-of-services limb. Balance is the Data Fiduciary; the parent and the kid are Data Principals; under DPDP Act Section 2(j), in respect of a child, "Data Principal" includes the parents or lawful guardian of such a child — the parent therefore exercises the kid's rights.


2. Statutory framework — what applies

The Indian personal-data-protection regime is dominated by the Digital Personal Data Protection Act, 2023, operationalised by the DPDP Rules 2025 (notified 14 November 2025 with phased commencement — the institutional provisions and the Board-establishment rules commenced first; the substantive Data-Fiduciary obligations commence per the notified schedule; Balance applies the full substantive regime voluntarily from the Effective date without waiting for the final commencement dates). Adjacent layers: the constitutional right to privacy (Article 21, Puttaswamy); the IT Act 2000; the IT Rules 2021; POCSO 2012; the CPA 2019 + E-Commerce Rules 2020; the Bharatiya Nyaya Sanhita, 2023; the CERT-In Directions 2022.

Instrument What it does Balance's posture
Constitution of India — Article 21 read with Justice K.S. Puttaswamy (Retd.) v Union of India (2017) 10 SCC 1 The fundamental right to privacy — informational privacy recognised as intrinsic to the right to life and personal liberty. The constitutional anchor. Treatment in §§ 3, 6, 13 below.
Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) The principal statute. Section 3(b) extraterritorial reach; Section 4 lawful processing only for a lawful purpose with consent (Section 6 — free, specific, informed, unconditional, unambiguous, clear affirmative action) or for certain legitimate uses (Section 7); Section 5 notice duty; Section 8 general obligations of the Data Fiduciary including 8(5) security safeguards and 8(6) breach intimation; Section 9 processing of personal data of children (under 18) — 9(1) verifiable parental consent before processing; 9(2) no processing likely to cause detrimental effect on the well-being of a child; 9(3) prohibition of tracking or behavioural monitoring of children or targeted advertising directed at children; 9(5) exemption power (operationalised by the DPDP Rules 2025 Fourth Schedule — Part B exempts specified purposes including processing "in the interests of safety of the child" from the 9(1)/9(3) restrictions to the extent necessary); Sections 11-14 Data-Principal rights (access, correction and erasure, grievance redressal, nomination); Section 16 cross-border transfers (permitted to every country not restricted by Central-Government notification — none restricted at the Effective date); Section 10 Significant Data Fiduciary tier (Balance not designated); Sections 18-28 the Data Protection Board of India; Section 33 + Schedule monetary penalties (up to INR 250 crore for failure of security safeguards; up to INR 200 crore for breach of children's-data obligations). The principal statute. Applies in full via Section 3(b). Treatment in §§ 3-8, 11 below.
DPDP Rules 2025 (notified 14 November 2025) Operationalises the DPDP Act: the form and manner of the Section 5 notice; the mechanics of verifiable parental consent (identity-and-age verification of the person identifying as the parent, using reliable details or a virtual token); the Fourth Schedule exemptions (Part B — purposes for which the Section 9(1) consent and Section 9(3) tracking/behavioural-monitoring restrictions do not apply to the extent necessary, including the safety of the child); breach-intimation form and timelines; retention-and-erasure mechanics; Consent-Manager registration (Balance does not act as a Consent Manager); Board procedure. Applies. Balance implements the verifiable-parental-consent mechanics at § 5 + § 7 below.
Information Technology Act, 2000 Section 67B — publishing / transmitting / browsing material depicting children in sexually explicit acts (imprisonment up to 5 years + fine on first conviction); Section 79 intermediary safe harbour (Balance does not rely on it — Balance is a closed family system, not a public intermediary surface); Section 69 lawful-interception powers with procedural safeguards. Applies. Treatment in §§ 13, 14 below.
IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 Due-diligence and grievance duties for intermediaries and publishers. Balance's parental-control service is a closed family system without a public content-hosting or content-discovery surface; the intermediary-specific duties are not engaged on the ordinary reading — Balance nonetheless honours the child-safety substance voluntarily. § 18 versioning protocol covers any classification change. Applies as a context-setting fact.
Protection of Children from Sexual Offences Act, 2012 (POCSO) The principal child-sexual-offences statute — Sections 13-15 (use of child for pornographic purposes; storage of child pornography), Section 19 mandatory reporting: any person who has apprehension or knowledge that an offence under POCSO is likely to be or has been committed shall report to the Special Juvenile Police Unit or the local police; Section 21 penalty for failure to report. Applies — the Section 19 duty binds Balance personnel. Treatment in § 14 below.
Consumer Protection Act, 2019 + Consumer Protection (E-Commerce) Rules, 2020 Consumer rights (Section 2(9)), unfair trade practices, product/service liability, the Central Consumer Protection Authority (CCPA), District/State/National Consumer Disputes Redressal Commissions; the E-Commerce Rules impose transparency, grievance-officer response timelines, and refund duties on e-commerce entities. Applies. Treatment in § 16 below.
CERT-In Directions of 28 April 2022 (under IT Act Section 70B(6)) Cyber-incident reporting to CERT-In within 6 hours of noticing specified categories of incidents; log-retention expectations. Applies to the extent Balance's incidents fall within the specified categories. Treatment in § 11 below.
EU adequacy None. India does not hold an EU adequacy decision under GDPR Article 45 at the Effective date. Context-setting fact; Balance has no India data residency (backend in the US — § 9 below).
Convention 108 / Budapest Convention India is not a party to Convention 108/108+ and has not acceded to the Budapest Convention. Cross-border lawful access runs via MLATs and letters rogatory (CrPC/BNSS provisions). Context-setting fact. Treatment in § 13 below.

(Any prospective Indian regulation governing automated processing, algorithmic decisions, or related techniques — including MeitY's advisories on AI systems, the National Strategy for Artificial Intelligence, any future Digital India Act, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 Data Protection Board of India

The principal enforcement body is the Data Protection Board of India (the "Board"), established under DPDP Act Sections 18-28 as a digital-by-design adjudicatory body: it receives personal-data-breach intimations, inquires into breaches of the Act on complaint or reference, and imposes the Section 33 monetary penalties. Appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) (Section 29).

Field Value
Name Data Protection Board of India
Parent ministry Ministry of Electronics and Information Technology (MeitY)
Website / complaint channel The Board's digital-office portal as notified under the DPDP Rules 2025 (published via https://www.meity.gov.in/)
Appeal Telecom Disputes Settlement and Appellate Tribunal (TDSAT), New Delhi — https://tdsat.gov.in/

An Indian resident may complain to the Board after exhausting the grievance-redressal opportunity with Balance (DPDP Act Section 13(3): the Data Principal shall first exhaust the grievance channel before approaching the Board). We accept all grievances and data-principal enquiries at (named individual: ) and respond within the timelines in § 6 below.

3.2 Other regulatory bodies

Body Subject matter URL / channel
Ministry of Electronics and Information Technology (MeitY) DPDP Act administration; IT Act; IT Rules 2021 https://www.meity.gov.in/
CERT-In Cyber-incident reporting (IT Act Section 70B) https://www.cert-in.org.in/incident@cert-in.org.in
Central Consumer Protection Authority (CCPA) + Consumer Commissions CPA 2019 + E-Commerce Rules 2020 https://consumerhelpline.gov.in/ — National Consumer Helpline 1915
National Cyber Crime Reporting Portal (Ministry of Home Affairs) Cybercrime including online CSAE — dedicated CSAM reporting track https://cybercrime.gov.in/ — Helpline 1930
Special Juvenile Police Unit / local police POCSO Section 19 mandatory reports Dial 112 (emergency); local SJPU
National Commission for Protection of Child Rights (NCPCR) Child-rights complaints https://ncpcr.gov.in/
Childline 1098 24/7 children's helpline dial 1098 (toll-free within India)

3.3 The contact person

The DPDP Act does not impose a general DPO mandate on non-Significant Data Fiduciaries; Section 5(1)(iii) + the DPDP Rules 2025 require publication of the business contact of a person able to answer questions about the processing. That person is , Director, BabaYaga Program, TOO — , published in this Annex, in the global Privacy Policy § 1, and at balance.babayagaprogram.com. If Balance is ever designated a Significant Data Fiduciary (Section 10), a Data Protection Officer based in India would be required; that designation has not occurred at the Effective date and the exposure is tracked internally (§ 18 versioning protocol).


The DPDP Act is a consent-first regime. Balance's mapping:


5. Children's rights overlay — Section 9 + the Fourth Schedule Part B anchor

Under the DPDP Act a child is a person under 18. Balance's India posture, stated plainly:

  1. The parent always consents; the kid never self-registers. A kid profile can only be created inside an authenticated parent account; the kid's device is paired by the parent's affirmative act. This is the Section 9(1) verifiable parental consent by design: the consenting adult is the account holder whose identity is verified through the email-verified account creation, the Google Play payment instrument where a subscription is purchased, and the DPDP-Rules-2025-conformant consent flow that itemises categories, purposes, recipients and rights. Balance observes due diligence that the person giving consent identifies as the parent or lawful guardian per the DPDP Rules 2025 verifiable-consent mechanics.
  2. The Fourth Schedule Part B anchor. Balance's monitoring, screen-time limits, app limits and task features are performed at the parent's direction, strictly for the safety, well-being and parental supervision of the child, and are never used for advertising, profiling, or any commercial purpose. To the extent any feature constitutes "tracking or behavioural monitoring" within Section 9(3), it is undertaken in the interests of safety of the child within the DPDP Rules 2025 Fourth Schedule Part B, restricted to the extent necessary for that purpose — which is exactly how the product is built (deterministic usage totals and limits, visible to the parent; no advertising surface; no profiling engine; no data sale).
  3. Section 9(2) — no processing likely to cause detrimental effect on the well-being of the child: Balance's DPIA (our Data Protection Impact Assessment) records the well-being analysis; the product surfaces no content feed, no social graph, no contact-by-strangers surface.
  4. Section 9(3) triple lock embraced. No tracking or behavioural monitoring for our purposes, no targeted advertising directed at children — a statutory command Balance embraces as product policy in every country (cross-reference Children's Privacy Notice § 6).
  5. Rights exercise: under Section 2(j) the parent exercises the kid's Data-Principal rights; the grievance channel in § 6 below is open to the parent on the kid's behalf and to the kid (age-appropriately) via the parent.

6. DPDP Act rights catalogue

An Indian resident has the following rights under DPDP Act Sections 11-14:

Requests may be submitted in English or in any Eighth-Schedule language (we will translate on receipt). Identity verification uses the parent's existing authentication credential; out-of-band verification is a last resort. The exercise of rights is free of charge.


The DPDP Rules 2025 require the Data Fiduciary to ensure verifiable consent of the parent before processing a child's personal data, adopting appropriate technical and organisational measures to check that the individual identifying as the parent is an adult who is identifiable if required. Balance's mechanism:


8. International data transfers from India — DPDP Act Section 16

DPDP Act Section 16 permits transfer of personal data outside India to every country except a country restricted by Central-Government notification. No country has been restricted at the Effective date — transfers from India to the United States (hosting) and Kazakhstan (controller access) are therefore lawful under Section 16 without a further transfer instrument. Balance nonetheless:


9. Data residency for Indian residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region (E2EE ciphertext only).
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Indian resident's data held in India? No. Every Indian resident's data is held in the United States. DPDP Act Section 16 permits the transfer (§ 8 above).
Where is the controller? Kazakhstan (BabaYaga Program, TOO), with administrative access to the US-hosted backend under written processor DPAs.
Is there an Indian establishment? No. Balance has no permanent establishment in India.

India does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date.


10. Sub-processors touching Indian-resident data

Sub-processor Role Location India transfer basis
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS + Privacy Policy (full handling in our internal vendor-handling plan) Hosts the FastAPI backend + MongoDB cluster United States DPDP Act Section 16 (no restricted-country notification); DPA + security controls on file per our international-transfer pack § 6; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores E2EE proof-media ciphertext + daily 30-day-rolling database backups United States (us multi-region) Section 16; Google Cloud Data Processing Addendum; ciphertext-only handling of proof media.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Indian kid + parent devices United States Section 16; push body deliberately free of sensitive content (the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States Section 16; Google DPA.
Google LLC — Google Play Billing Processes subscription purchases United States / India (Google Play India) Section 16; Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Indian parent users United States Section 16; DPA on file.

Every sub-processor is bound by a written data-processing agreement that forbids processing for any purpose other than performing the engaged service. The full list with DPA status is at our sub-processor register.


11. Breach notification — DPDP Act Section 8(6) + DPDP Rules 2025 + CERT-In Directions 2022

Audience Trigger Deadline Channel
Affected Data Principals Any personal data breach (DPDP Act Section 2(u): any unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability). Without delay, in the form and manner of the DPDP Rules 2025 — plain-language description, consequences, mitigation, safety measures the individual may take, and our contact. Direct email to the affected parent; in-app banner; public incident page if email is undeliverable.
Data Protection Board of India The same breach. Per the DPDP Rules 2025 two-stage intimation: prompt initial intimation, followed by the detailed report within 72 hours (extendable on request). The Board's digital portal, filed by the Privacy Officer.
CERT-In Incidents within the categories specified by the CERT-In Directions 2022. Within 6 hours of noticing. incident@cert-in.org.in / CERT-In portal.
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). POCSO Section 19 route (SJPU/local police) + https://cybercrime.gov.in/ + (where applicable) NCMEC.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9. Note the DPDP Act notification duty is not harm-thresholded — every personal data breach is notifiable to the affected Data Principals and the Board.


12. Cookies, spam, and electronic direct marketing

India has no standalone cookies statute; consent-based processing under the DPDP Act covers cookie-equivalent storage. The Balance app deploys strictly-necessary storage only (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache), covered by the sign-up consent. The public legal-documents site (balance.babayagaprogram.com) uses no analytics, no advertising cookies, no third-party trackers, no fingerprinting. Balance does not send electronic direct marketing to Indian residents — the only email is transactional (account creation, password reset, subscription receipts, security alerts, parent-action notifications). DPDP Act Section 9(3)'s ban on targeted advertising directed at children is honoured absolutely. The TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 (unsolicited commercial communication) are not engaged because Balance sends no commercial SMS/voice communication.


13. Lawful-access requests and the encryption posture

Indian authorities may serve lawful-access requests via IT Act Section 69 / 69A / 69B orders (with their procedural safeguards), orders of a court, CrPC/BNSS production summonses, or MLAT/letters-rogatory channels (India is not a Budapest Convention party). The Balance architectural posture:

Full encryption posture: our encryption-posture record.


14. CSAE reporting routes — India

An Indian resident (parent, kid, or third party) may report a CSAE concern via:

The full CSAE Country Routing Table is in Child Safety Standards § 8.5.


15. Complaint routes (summary)

Authority Subject matter Channel
Data Protection Board of India DPDP Act breaches (after exhausting our grievance channel — Section 13(3)) Board digital portal via https://www.meity.gov.in/; appeal to TDSAT
CCPA / Consumer Commissions CPA 2019 + E-Commerce Rules 2020 https://consumerhelpline.gov.in/ — Helpline 1915
National Cyber Crime Reporting Portal Cybercrime + online CSAE https://cybercrime.gov.in/1930
NCPCR Child-rights complaints https://ncpcr.gov.in/
Courts Constitutional (Art 32/226) + civil + criminal routes Per jurisdiction

An Indian resident should first raise the matter with us at (Section 13(3) exhaustion); we acknowledge within one business day and resolve within 30 days at the outside.


16. Consumer rights — the CPA 2019 + E-Commerce Rules 2020 overlay


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the bundle:


End of India Country Annex.

← Back to Privacy Policy · Children's Privacy Notice